)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"8c3f61d5676d425e75c44b0b432c48be40c7e8bb","unresolved":true,"context_lines":[{"line_number":4,"context_line":"Commit:     settkepa \u003cSridharKumar.Ettkepalli@windriver.com\u003e"},{"line_number":5,"context_line":"CommitDate: 2026-09-14 10:05:51 -0400"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"NetApp ONTAP: skip SVM tunnel header for SVM users"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"With the NetApp ONTAP REST client (netapp_use_legacy_client\u003dfalse),"},{"line_number":10,"context_line":"_build_headers() in RestNaServer adds the X-Dot-SVM-Name tunneling"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":3,"id":"1bbdec64_784c0716","line":7,"updated":"2026-09-15 13:40:36.000000000","message":"I feel release note can be shortened. This contains too much implementation details, which is not needed in the release notes.","commit_id":"eca63dcd570cf49e8f01f9fea9a5af20bb83d4a4"},{"author":{"_account_id":36171,"name":"jayaanand borra","display_name":"jayaanand borra","email":"jayaanand.borra@netapp.com","username":"jayaanan","status":"netapp"},"change_message_id":"cec6df82b2a223c9d331f5698c07eebaaab9ab79","unresolved":true,"context_lines":[{"line_number":4,"context_line":"Commit:     settkepa \u003cSridharKumar.Ettkepalli@windriver.com\u003e"},{"line_number":5,"context_line":"CommitDate: 2026-09-14 10:05:51 -0400"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"NetApp ONTAP: skip SVM tunnel header for SVM users"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"With the NetApp ONTAP REST client (netapp_use_legacy_client\u003dfalse),"},{"line_number":10,"context_line":"_build_headers() in RestNaServer adds the X-Dot-SVM-Name tunneling"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":3,"id":"383e3003_da9d722a","line":7,"in_reply_to":"1bbdec64_784c0716","updated":"2026-09-15 14:04:59.000000000","message":"Agree with Anoop: this commit message is too much implementation\ndetail. Please shorten it.\nAlso add a reno under releasenotes/notes/ (fixes:). This is\noperator-visible: REST + SVM-scoped credentials currently cannot\nstart cinder-volume. Match the style of\nnetapp_fix_svm_scoped_permissions.yaml / bug-1924798.","commit_id":"eca63dcd570cf49e8f01f9fea9a5af20bb83d4a4"},{"author":{"_account_id":38864,"name":"Sridhar Kumar Ettkepalli","display_name":"Sridhar","email":"sridharkumar.ettkepalli@windriver.com","username":"settkepa"},"change_message_id":"a324c81455e2179977a35e1a4ed2121033879abb","unresolved":false,"context_lines":[{"line_number":4,"context_line":"Commit:     settkepa \u003cSridharKumar.Ettkepalli@windriver.com\u003e"},{"line_number":5,"context_line":"CommitDate: 2026-09-14 10:05:51 -0400"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"NetApp ONTAP: skip SVM tunnel header for SVM users"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"With the NetApp ONTAP REST client (netapp_use_legacy_client\u003dfalse),"},{"line_number":10,"context_line":"_build_headers() in RestNaServer adds the X-Dot-SVM-Name tunneling"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":3,"id":"f76b0084_e7bec0d2","line":7,"in_reply_to":"383e3003_da9d722a","updated":"2026-09-15 16:15:56.000000000","message":"Done — shortened the commit body and added a releasenotes/notes/ fixes note (operator-visible: REST + SVM-scoped credentials could not start cinder-volume), matching the existing netapp reno style.","commit_id":"eca63dcd570cf49e8f01f9fea9a5af20bb83d4a4"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"bbe4a69d488928fb8104a69ed8d8fd762701ca98","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"40f2702a_164cbf86","updated":"2026-09-15 13:41:06.000000000","message":"Code looks good to me, please take a look at the release notes comment.","commit_id":"eca63dcd570cf49e8f01f9fea9a5af20bb83d4a4"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"8c3f61d5676d425e75c44b0b432c48be40c7e8bb","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"1efb29ea_1373bc17","updated":"2026-09-15 13:40:36.000000000","message":"Run-NetApp CI","commit_id":"eca63dcd570cf49e8f01f9fea9a5af20bb83d4a4"},{"author":{"_account_id":36171,"name":"jayaanand borra","display_name":"jayaanand borra","email":"jayaanand.borra@netapp.com","username":"jayaanan","status":"netapp"},"change_message_id":"cec6df82b2a223c9d331f5698c07eebaaab9ab79","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"1e46f2e4_9ec8ffea","updated":"2026-09-15 14:04:59.000000000","message":"Thanks for fixing this in RestNaServer rather than sprinkling\nenable_tunneling\u003dFalse. That is the right layer: send_request()\ndefaults to tunneling, so create/delete/snapshot/clone/extend/attach\nall hit 2621712 today.\n\nPlease address the str(code) fallback, best-effort probe, and reno.\nI would also like a word on whether the 9.15.1 live run actually\ntook the 2621712 retry or only the security/accounts hit.\n\nWaiting on NetApp CI for PS3 (Run-NetApp CI is in flight).","commit_id":"eca63dcd570cf49e8f01f9fea9a5af20bb83d4a4"},{"author":{"_account_id":38864,"name":"Sridhar Kumar Ettkepalli","display_name":"Sridhar","email":"sridharkumar.ettkepalli@windriver.com","username":"settkepa"},"change_message_id":"d1848ae6cf27b10dc175d25fdb9b9d1f78d89aa9","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"81c6b2b1_41383729","updated":"2026-09-14 17:11:42.000000000","message":"recheck","commit_id":"eca63dcd570cf49e8f01f9fea9a5af20bb83d4a4"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"e84f30b15a443f9426fbbe6a05e097dd5209c50a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"abc410e6_0205e5e7","updated":"2026-09-16 09:25:01.000000000","message":"LGTM - and CI has passed.","commit_id":"c12186a0a15ddb773527c9d91fed18c3118ac649"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"f96470c6e8f4b15fca8d8e219144dd461331a1a2","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"93845a1f_2a3fb6c6","updated":"2026-09-16 05:19:52.000000000","message":"run-NetApp CI","commit_id":"c12186a0a15ddb773527c9d91fed18c3118ac649"}],"cinder/tests/unit/volume/drivers/netapp/dataontap/client/test_api.py":[{"author":{"_account_id":36171,"name":"jayaanand borra","display_name":"jayaanand borra","email":"jayaanand.borra@netapp.com","username":"jayaanan","status":"netapp"},"change_message_id":"cec6df82b2a223c9d331f5698c07eebaaab9ab79","unresolved":true,"context_lines":[{"line_number":1098,"context_line":"        self.rest_client._is_svm_scoped \u003d False"},{"line_number":1099,"context_line":"        self.mock_object(self.rest_client, \u0027get_vserver\u0027,"},{"line_number":1100,"context_line":"                         return_value\u003dzapi_fakes.VSERVER_NAME)"},{"line_number":1101,"context_line":"        error_body \u003d {\u0027error\u0027: {\u0027code\u0027: netapp_api.ESVM_CONTEXT_ALREADY_SET,"},{"line_number":1102,"context_line":"                                \u0027message\u0027: \u0027Cannot set the svm context\u0027}}"},{"line_number":1103,"context_line":"        ok_body \u003d {\u0027records\u0027: [{\u0027name\u0027: \u0027vol1\u0027}]}"},{"line_number":1104,"context_line":"        mock_send \u003d self.mock_object("}],"source_content_type":"text/x-python","patch_set":3,"id":"bebc872b_eaceaf7f","line":1101,"updated":"2026-09-15 14:04:59.000000000","message":"Please also mock {\u0027error\u0027: {\u0027code\u0027: 2621712, ...}} — the type\nERROR_RESPONSE_REST already uses. Cover: retry still failing raises\nNaApiError; mixed svm+cluster records stay cluster-scoped; username\nNone; probe decode failure returns False.","commit_id":"eca63dcd570cf49e8f01f9fea9a5af20bb83d4a4"},{"author":{"_account_id":38864,"name":"Sridhar Kumar Ettkepalli","display_name":"Sridhar","email":"sridharkumar.ettkepalli@windriver.com","username":"settkepa"},"change_message_id":"a324c81455e2179977a35e1a4ed2121033879abb","unresolved":false,"context_lines":[{"line_number":1098,"context_line":"        self.rest_client._is_svm_scoped \u003d False"},{"line_number":1099,"context_line":"        self.mock_object(self.rest_client, \u0027get_vserver\u0027,"},{"line_number":1100,"context_line":"                         return_value\u003dzapi_fakes.VSERVER_NAME)"},{"line_number":1101,"context_line":"        error_body \u003d {\u0027error\u0027: {\u0027code\u0027: netapp_api.ESVM_CONTEXT_ALREADY_SET,"},{"line_number":1102,"context_line":"                                \u0027message\u0027: \u0027Cannot set the svm context\u0027}}"},{"line_number":1103,"context_line":"        ok_body \u003d {\u0027records\u0027: [{\u0027name\u0027: \u0027vol1\u0027}]}"},{"line_number":1104,"context_line":"        mock_send \u003d self.mock_object("}],"source_content_type":"text/x-python","patch_set":3,"id":"a8a8c0b5_e9baafc6","line":1101,"in_reply_to":"bebc872b_eaceaf7f","updated":"2026-09-15 16:15:56.000000000","message":"Added: the retry test is ddt\u0027d over int 2621712 and string \u00272621712\u0027; a retry that still fails re-raises NaApiError; a name matching mixed svm+cluster records stays cluster-scoped; username\u003dNone returns False with no HTTP; and an unparseable/exception probe response returns False without escaping.","commit_id":"eca63dcd570cf49e8f01f9fea9a5af20bb83d4a4"}],"cinder/volume/drivers/netapp/dataontap/client/api.py":[{"author":{"_account_id":37173,"name":"Alex Fernandes Figueirêdo","display_name":"Alex Figueiredo","email":"alex.fernandesfigueiredo@windriver.com","username":"afernand"},"change_message_id":"5004b4cc021a9e0f6556733a37ac8029e73dc2b5","unresolved":true,"context_lines":[{"line_number":881,"context_line":"            self._is_svm_scoped \u003d self._detect_svm_scope()"},{"line_number":882,"context_line":"        return self._is_svm_scoped"},{"line_number":883,"context_line":""},{"line_number":884,"context_line":"    def _detect_svm_scope(self):"},{"line_number":885,"context_line":"        \"\"\"Probe /api/svm/svms to classify the account scope."},{"line_number":886,"context_line":""},{"line_number":887,"context_line":"        Returns True when exactly one SVM is visible (SVM-scoped account),"},{"line_number":888,"context_line":"        False otherwise (cluster-scoped account or an indeterminate probe)."},{"line_number":889,"context_line":"        \"\"\""},{"line_number":890,"context_line":"        headers \u003d {"},{"line_number":891,"context_line":"            \"Accept\": \"application/json\","},{"line_number":892,"context_line":"            \"Content-Type\": \"application/json\","}],"source_content_type":"text/x-python","patch_set":2,"id":"20545345_1dee7385","line":889,"range":{"start_line":884,"start_character":0,"end_line":889,"end_character":11},"updated":"2026-09-11 21:56:47.000000000","message":"What happens for cluster-scoped accounts in a single SVM cluster?\n\n`GET /api/svm/svms` lists data SVMs, so a cluster-scoped account on a cluster\nwith a single data SVM also returns `num_records \u003d\u003d 1`.\n\nCan you take the following options into account?\n\n1. Ask ONTAP directly: `GET /api/security/accounts?name\u003d\u003cuser\u003e\u0026fields\u003dscope,owner`\n   returns scope: \"svm\"|\"cluster\". Keep `num_records` as a fallback.\n2. `GET /api/cluster` as discriminator (403 for svm-scoped accounts, 200 for cluster-scoped accounts).\n3. Detect reactively: catch error, cache and retry without the header.\n\nIf you decide to keep the current heuristic for some reason, describe the\nexpectation for this single SVM scenario in the commit message.","commit_id":"6c2e326f349a4440643a8b2a56bed1f9c8d80ff6"},{"author":{"_account_id":38864,"name":"Sridhar Kumar Ettkepalli","display_name":"Sridhar","email":"sridharkumar.ettkepalli@windriver.com","username":"settkepa"},"change_message_id":"2991d8eb7f9968921215d49ef62a2dd010f4c411","unresolved":true,"context_lines":[{"line_number":881,"context_line":"            self._is_svm_scoped \u003d self._detect_svm_scope()"},{"line_number":882,"context_line":"        return self._is_svm_scoped"},{"line_number":883,"context_line":""},{"line_number":884,"context_line":"    def _detect_svm_scope(self):"},{"line_number":885,"context_line":"        \"\"\"Probe /api/svm/svms to classify the account scope."},{"line_number":886,"context_line":""},{"line_number":887,"context_line":"        Returns True when exactly one SVM is visible (SVM-scoped account),"},{"line_number":888,"context_line":"        False otherwise (cluster-scoped account or an indeterminate probe)."},{"line_number":889,"context_line":"        \"\"\""},{"line_number":890,"context_line":"        headers \u003d {"},{"line_number":891,"context_line":"            \"Accept\": \"application/json\","},{"line_number":892,"context_line":"            \"Content-Type\": \"application/json\","}],"source_content_type":"text/x-python","patch_set":2,"id":"79e8c2fe_236d75fb","line":889,"range":{"start_line":884,"start_character":0,"end_line":889,"end_character":11},"in_reply_to":"20545345_1dee7385","updated":"2026-09-14 13:39:38.000000000","message":"Good catch — you\u0027re right, num_records \u003d\u003d 1 misclassifies a cluster-scoped account on a cluster with a single data SVM, which would wrongly suppress X-Dot-SVM-Name for it. Thanks for the detailed options.\n\nI\u0027ll go with a hybrid of (1) and (3):\n\n- Primary: GET /api/security/accounts?name\u003d\u003cuser\u003e\u0026fields\u003dscope and use scope \u003d\u003d \"svm\". This is authoritative and fixes the single-SVM-cluster false positive directly.\n- Fallback: reactive detection. If the scope query can\u0027t be answered — e.g. an SVM-scoped (vsadmin) account that isn\u0027t permitted to read /api/security/accounts — send the header as today, and on the 2621712 \"Cannot set the svm context\" error, cache svm-scoped and retry without it.\n\nI chose the reactive fallback over keeping the num_records heuristic because the heuristic can still misclassify in exactly the single-SVM case you flagged, whereas reacting to 2621712 cannot produce a false positive regardless of RBAC visibility. The scope caching stays one-time as before.\n\nI\u0027ll leave option (2) (GET /api/cluster 403/200) aside — it keys off an error code that a custom cluster-scoped role could also be denied, so it\u0027s less reliable than asking for the scope directly.\n\nWill push a new patchset with this plus unit tests for: scope\u003dsvm/scope\u003dcluster from security/accounts, the cluster-scoped single-SVM case, and the reactive 2621712-retry fallback. Thanks again.","commit_id":"6c2e326f349a4440643a8b2a56bed1f9c8d80ff6"},{"author":{"_account_id":38864,"name":"Sridhar Kumar Ettkepalli","display_name":"Sridhar","email":"sridharkumar.ettkepalli@windriver.com","username":"settkepa"},"change_message_id":"78dfbf025e19cb20f679b170fdb9b55864e7eff3","unresolved":false,"context_lines":[{"line_number":881,"context_line":"            self._is_svm_scoped \u003d self._detect_svm_scope()"},{"line_number":882,"context_line":"        return self._is_svm_scoped"},{"line_number":883,"context_line":""},{"line_number":884,"context_line":"    def _detect_svm_scope(self):"},{"line_number":885,"context_line":"        \"\"\"Probe /api/svm/svms to classify the account scope."},{"line_number":886,"context_line":""},{"line_number":887,"context_line":"        Returns True when exactly one SVM is visible (SVM-scoped account),"},{"line_number":888,"context_line":"        False otherwise (cluster-scoped account or an indeterminate probe)."},{"line_number":889,"context_line":"        \"\"\""},{"line_number":890,"context_line":"        headers \u003d {"},{"line_number":891,"context_line":"            \"Accept\": \"application/json\","},{"line_number":892,"context_line":"            \"Content-Type\": \"application/json\","}],"source_content_type":"text/x-python","patch_set":2,"id":"5240ba54_540da1a9","line":889,"range":{"start_line":884,"start_character":0,"end_line":889,"end_character":11},"in_reply_to":"79e8c2fe_236d75fb","updated":"2026-09-15 16:16:23.000000000","message":"Done","commit_id":"6c2e326f349a4440643a8b2a56bed1f9c8d80ff6"},{"author":{"_account_id":36171,"name":"jayaanand borra","display_name":"jayaanand borra","email":"jayaanand.borra@netapp.com","username":"jayaanan","status":"netapp"},"change_message_id":"cec6df82b2a223c9d331f5698c07eebaaab9ab79","unresolved":true,"context_lines":[{"line_number":866,"context_line":"        # while in an existing svm context\"), which breaks driver init. Detect"},{"line_number":867,"context_line":"        # the account scope once and suppress the header for SVM-scoped"},{"line_number":868,"context_line":"        # accounts so every tunneling-enabled call site is handled uniformly."},{"line_number":869,"context_line":"        if enable_tunneling and not self._get_is_svm_scoped():"},{"line_number":870,"context_line":"            headers[\"X-Dot-SVM-Name\"] \u003d self.get_vserver()"},{"line_number":871,"context_line":""},{"line_number":872,"context_line":"        return headers"}],"source_content_type":"text/x-python","patch_set":3,"id":"4bfe335c_3e7fb95e","line":869,"updated":"2026-09-15 14:04:59.000000000","message":"_build_headers() should not do HTTP. On the first tunneled call this\nruns _detect_svm_scope() → send_http_request(), rebuilds self._session,\nand yields inside the volume thread pool.\n\nRestClient.__init__ already calls get_ontap_version() after\nset_vserver() on a single thread. Detect there (or via an explicit\nRestNaServer helper) and let _build_headers() only read the cached\nbool.\n\nIf you keep lazy detect, make SVM-scoped sticky so a late probe False\ncannot overwrite a concurrent 2621712 retry that already set True.\nLock only the cache write, not the probe RTT. This is not a\ncoordination.synchronized candidate.","commit_id":"eca63dcd570cf49e8f01f9fea9a5af20bb83d4a4"},{"author":{"_account_id":38864,"name":"Sridhar Kumar Ettkepalli","display_name":"Sridhar","email":"sridharkumar.ettkepalli@windriver.com","username":"settkepa"},"change_message_id":"a324c81455e2179977a35e1a4ed2121033879abb","unresolved":false,"context_lines":[{"line_number":866,"context_line":"        # while in an existing svm context\"), which breaks driver init. Detect"},{"line_number":867,"context_line":"        # the account scope once and suppress the header for SVM-scoped"},{"line_number":868,"context_line":"        # accounts so every tunneling-enabled call site is handled uniformly."},{"line_number":869,"context_line":"        if enable_tunneling and not self._get_is_svm_scoped():"},{"line_number":870,"context_line":"            headers[\"X-Dot-SVM-Name\"] \u003d self.get_vserver()"},{"line_number":871,"context_line":""},{"line_number":872,"context_line":"        return headers"}],"source_content_type":"text/x-python","patch_set":3,"id":"e531d0b3_4a641cd1","line":869,"in_reply_to":"4bfe335c_3e7fb95e","updated":"2026-09-15 16:15:56.000000000","message":"Done. Scope detection now runs once in RestClient.__init__ (via a new RestNaServer.detect_and_cache_svm_scope helper) right after set_vserver() and before get_ontap_version(), which issues the first tunneled /cluster/ call. _build_headers() only reads the cached bool now and performs no I/O. SVM-scoped is sticky: the reactive 2621712 retry sets it True and detect_and_cache never clears an already-True cache, so a late detection can\u0027t override it. No coordination.synchronized used.","commit_id":"eca63dcd570cf49e8f01f9fea9a5af20bb83d4a4"},{"author":{"_account_id":36171,"name":"jayaanand borra","display_name":"jayaanand borra","email":"jayaanand.borra@netapp.com","username":"jayaanan","status":"netapp"},"change_message_id":"cec6df82b2a223c9d331f5698c07eebaaab9ab79","unresolved":true,"context_lines":[{"line_number":909,"context_line":"                                                  \u0027fields\u0027: \u0027scope\u0027})"},{"line_number":910,"context_line":"        try:"},{"line_number":911,"context_line":"            _code, response \u003d self.send_http_request(\u0027get\u0027, url, None, headers)"},{"line_number":912,"context_line":"        except NaApiError as e:"},{"line_number":913,"context_line":"            LOG.debug(\u0027Could not read account scope from security/accounts \u0027"},{"line_number":914,"context_line":"                      \u0027(%s); assuming cluster-scoped for now. The scope is \u0027"},{"line_number":915,"context_line":"                      \u0027corrected reactively if a request is rejected with \u0027"}],"source_content_type":"text/x-python","patch_set":3,"id":"9278d97d_6c94fe2f","line":912,"updated":"2026-09-15 14:04:59.000000000","message":"This probe is described as best-effort but only catches NaApiError.\nsend_http_request() json-decodes *after* its except Exception, so an\nHTML 403 or a non-dict records[0] raises out of _build_headers() and\nfails the caller\u0027s request (get_ontap_version during RestClient.__init__,\ni.e. do_setup).\n\nCertificate auth also constructs RestNaServer without username\n(client_cmode_rest.py), so this becomes name\u003dNone.\n\nPlease:\n- return False immediately when not self._username\n- wrap the probe in except Exception\n- treat as SVM-scoped only if every record has scope \u003d\u003d \"svm\"\n  (a cluster user named like an SVM user can return mixed rows;\n  records[0] would drop X-Dot-SVM-Name for a cluster admin)","commit_id":"eca63dcd570cf49e8f01f9fea9a5af20bb83d4a4"},{"author":{"_account_id":38864,"name":"Sridhar Kumar Ettkepalli","display_name":"Sridhar","email":"sridharkumar.ettkepalli@windriver.com","username":"settkepa"},"change_message_id":"a324c81455e2179977a35e1a4ed2121033879abb","unresolved":false,"context_lines":[{"line_number":909,"context_line":"                                                  \u0027fields\u0027: \u0027scope\u0027})"},{"line_number":910,"context_line":"        try:"},{"line_number":911,"context_line":"            _code, response \u003d self.send_http_request(\u0027get\u0027, url, None, headers)"},{"line_number":912,"context_line":"        except NaApiError as e:"},{"line_number":913,"context_line":"            LOG.debug(\u0027Could not read account scope from security/accounts \u0027"},{"line_number":914,"context_line":"                      \u0027(%s); assuming cluster-scoped for now. The scope is \u0027"},{"line_number":915,"context_line":"                      \u0027corrected reactively if a request is rejected with \u0027"}],"source_content_type":"text/x-python","patch_set":3,"id":"7f486430_afd4b9f4","line":912,"in_reply_to":"9278d97d_6c94fe2f","updated":"2026-09-15 16:15:56.000000000","message":"All three addressed: the method returns False immediately when self._username is unset (certificate auth), the probe is wrapped in except Exception (so an HTML/403 body that fails to json-decode, or a non-dict record, cannot escape into get_ontap_version/do_setup), and it classifies SVM-scoped only when every returned record has scope \u003d\u003d \"svm\" (a cluster admin whose name also matches an SVM account is no longer misclassified from records[0]).","commit_id":"eca63dcd570cf49e8f01f9fea9a5af20bb83d4a4"},{"author":{"_account_id":36171,"name":"jayaanand borra","display_name":"jayaanand borra","email":"jayaanand.borra@netapp.com","username":"jayaanan","status":"netapp"},"change_message_id":"cec6df82b2a223c9d331f5698c07eebaaab9ab79","unresolved":true,"context_lines":[{"line_number":1002,"context_line":"        # the tunneling header, and retry the request once. This is the"},{"line_number":1003,"context_line":"        # fallback for accounts whose scope could not be read up front from"},{"line_number":1004,"context_line":"        # /api/security/accounts."},{"line_number":1005,"context_line":"        if (code \u003d\u003d ESVM_CONTEXT_ALREADY_SET"},{"line_number":1006,"context_line":"                and \"X-Dot-SVM-Name\" in headers):"},{"line_number":1007,"context_line":"            LOG.debug(\u0027Request rejected with error %s; the account is \u0027"},{"line_number":1008,"context_line":"                      \u0027SVM-scoped. Retrying without the X-Dot-SVM-Name \u0027"}],"source_content_type":"text/x-python","patch_set":3,"id":"6b66bf90_e7484b29","line":1005,"updated":"2026-09-15 14:04:59.000000000","message":"The vsadmin fallback will not fire if ONTAP puts 2621712 in JSON as a\nnumber. jsonutils.loads() then yields int, and\n\ncode \u003d\u003d ESVM_CONTEXT_ALREADY_SET   # \u00272621712\u0027\n\nis False. This tree already models REST error codes as ints\n(ERROR_RESPONSE_REST uses \"code\": 1100). The new unit test passes the\nstring constant, so it does not catch this.\n\nDefault vsadmin often cannot read /api/security/accounts, so this retry\nis the path that has to work. Please use str(code) and ddt both\n\u00272621712\u0027 and 2621712.\n\n   if (str(code) \u003d\u003d ESVM_CONTEXT_ALREADY_SET\n            and \"X-Dot-SVM-Name\" in headers):","commit_id":"eca63dcd570cf49e8f01f9fea9a5af20bb83d4a4"},{"author":{"_account_id":38864,"name":"Sridhar Kumar Ettkepalli","display_name":"Sridhar","email":"sridharkumar.ettkepalli@windriver.com","username":"settkepa"},"change_message_id":"a324c81455e2179977a35e1a4ed2121033879abb","unresolved":false,"context_lines":[{"line_number":1002,"context_line":"        # the tunneling header, and retry the request once. This is the"},{"line_number":1003,"context_line":"        # fallback for accounts whose scope could not be read up front from"},{"line_number":1004,"context_line":"        # /api/security/accounts."},{"line_number":1005,"context_line":"        if (code \u003d\u003d ESVM_CONTEXT_ALREADY_SET"},{"line_number":1006,"context_line":"                and \"X-Dot-SVM-Name\" in headers):"},{"line_number":1007,"context_line":"            LOG.debug(\u0027Request rejected with error %s; the account is \u0027"},{"line_number":1008,"context_line":"                      \u0027SVM-scoped. Retrying without the X-Dot-SVM-Name \u0027"}],"source_content_type":"text/x-python","patch_set":3,"id":"42347166_0f54b50e","line":1005,"in_reply_to":"6b66bf90_e7484b29","updated":"2026-09-15 16:15:56.000000000","message":"Good catch — fixed. The comparison is now str(code) \u003d\u003d ESVM_CONTEXT_ALREADY_SET, and the unit test is parametrized over both the int 2621712 and the string \u00272621712\u0027. The earlier test only passed the string constant, which masked this.","commit_id":"eca63dcd570cf49e8f01f9fea9a5af20bb83d4a4"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"a87e2efc9446cc4337b45b0a885722fc7bbc38f4","unresolved":true,"context_lines":[{"line_number":1002,"context_line":"        # the tunneling header, and retry the request once. This is the"},{"line_number":1003,"context_line":"        # fallback for accounts whose scope could not be read up front from"},{"line_number":1004,"context_line":"        # /api/security/accounts."},{"line_number":1005,"context_line":"        if (code \u003d\u003d ESVM_CONTEXT_ALREADY_SET"},{"line_number":1006,"context_line":"                and \"X-Dot-SVM-Name\" in headers):"},{"line_number":1007,"context_line":"            LOG.debug(\u0027Request rejected with error %s; the account is \u0027"},{"line_number":1008,"context_line":"                      \u0027SVM-scoped. Retrying without the X-Dot-SVM-Name \u0027"}],"source_content_type":"text/x-python","patch_set":3,"id":"d7ec6c2e_8926d0bf","line":1005,"in_reply_to":"6b66bf90_e7484b29","updated":"2026-09-15 16:00:47.000000000","message":"I was speculating this to be an issue. But as long as ONTAP returns int we are good right?","commit_id":"eca63dcd570cf49e8f01f9fea9a5af20bb83d4a4"},{"author":{"_account_id":38864,"name":"Sridhar Kumar Ettkepalli","display_name":"Sridhar","email":"sridharkumar.ettkepalli@windriver.com","username":"settkepa"},"change_message_id":"a324c81455e2179977a35e1a4ed2121033879abb","unresolved":false,"context_lines":[{"line_number":1002,"context_line":"        # the tunneling header, and retry the request once. This is the"},{"line_number":1003,"context_line":"        # fallback for accounts whose scope could not be read up front from"},{"line_number":1004,"context_line":"        # /api/security/accounts."},{"line_number":1005,"context_line":"        if (code \u003d\u003d ESVM_CONTEXT_ALREADY_SET"},{"line_number":1006,"context_line":"                and \"X-Dot-SVM-Name\" in headers):"},{"line_number":1007,"context_line":"            LOG.debug(\u0027Request rejected with error %s; the account is \u0027"},{"line_number":1008,"context_line":"                      \u0027SVM-scoped. Retrying without the X-Dot-SVM-Name \u0027"}],"source_content_type":"text/x-python","patch_set":3,"id":"324f624e_69c03b40","line":1005,"in_reply_to":"d7ec6c2e_8926d0bf","updated":"2026-09-15 16:15:56.000000000","message":"ONTAP returns the error code as an int in the REST JSON body (the tree\u0027s ERROR_RESPONSE_REST fake uses \"code\": 1100), which is exactly why the original code \u003d\u003d \u00272621712\u0027 string comparison never matched. With the str(code) fix we now match whether ONTAP returns it as an int or a string, so we\u0027re not relying on the int assumption either way.","commit_id":"eca63dcd570cf49e8f01f9fea9a5af20bb83d4a4"}]}
